Security Advisory

CVE-2023-2742

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-06-19 10:52:43
Last updated 2025-04-23 16:20:59
Assigner WPScan
State PUBLISHED

Description

The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.